generated: '2026-07-25' method: searched probe: true source: https://www.lexisnexis.com/.well-known/security.txt policy: [] contact: - mailto:security@lexisnexis.com encryption: - https://lexisnexis.com/gpg_disclosure_public.txt preferred_languages: - en expires: '2027-04-10T16:30:00.000Z' canonical: https://lexisnexis.com/.well-known/security.txt hiring: https://www.lexisnexis.com/en-us/about-us/careers.page pgp_signed: true bug_bounty: program: null platform: null note: >- No public bug-bounty program was found on HackerOne, Bugcrowd or Intigriti for LexisNexis Risk Solutions, and no responsible-disclosure page was found on risk.lexisnexis.com (/corporate/vulnerability-disclosure and /corporate/security both 404). evidence: - source: https://www.lexisnexis.com/.well-known/security.txt kind: security.txt status: 200 note: >- RFC 9116 document, PGP-signed, served on the parent registrable domain lexisnexis.com. risk.lexisnexis.com is a subdomain of that registrable domain, so this security.txt is the reporting channel of record for the Risk Solutions web property. There is no Policy: field - only a Contact: mailbox. - source: well-known/lexisnexis-risk-solutions-security.txt kind: harvested-copy notes: >- The security.txt carries Contact and Encryption but no Policy URL, so the disclosure channel is an email mailbox rather than a published disclosure programme. Recorded honestly as a contact-only channel.